
Oomph Hidden Tags Security & Risk Analysis
wordpress.org/plugins/oomph-hidden-tagsHide certain tags from tag lists and tag clouds. Allow capable users to see hidden tags with the see_hidden_tags capability.
Is Oomph Hidden Tags Safe to Use in 2026?
Generally Safe
Score 85/100Oomph Hidden Tags has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "oomph-hidden-tags" v0.2 exhibits a generally good security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the code signals indicate no dangerous functions, file operations, or external HTTP requests. All SQL queries are properly prepared, and there are no reported taint flows with unsanitized paths. The presence of capability checks is also a positive sign for access control.
However, there are a couple of areas that warrant attention. The fact that 100% of the SQL queries are using prepared statements is excellent, but the presence of only 2 capability checks across the entire plugin, especially with 13 total outputs, could indicate that some outputs might not be adequately protected if they were to become user-controllable in the future. The absence of any nonce checks is a potential concern, although with no identified AJAX handlers or shortcodes, this risk is currently mitigated. The plugin also has no recorded vulnerability history, suggesting a stable and secure past, which is a strong indicator of good development practices.
In conclusion, "oomph-hidden-tags" v0.2 appears to be a securely coded plugin with a minimal attack surface and good practices regarding SQL. The main area for potential improvement would be to ensure robust capability checks and output escaping for all data, particularly if the plugin evolves and gains more interactive features. The lack of vulnerabilities and taint flows is highly reassuring.
Key Concerns
- No nonce checks present
- Limited capability checks for outputs
Oomph Hidden Tags Security Vulnerabilities
Oomph Hidden Tags Code Analysis
Output Escaping
Oomph Hidden Tags Attack Surface
WordPress Hooks 5
Maintenance & Trust
Oomph Hidden Tags Maintenance & Trust
Maintenance Signals
Community Trust
Oomph Hidden Tags Alternatives
Hidden Tags
hidden-tags
Hide certain tags/categories from the public
Ultimate Category Excluder
ultimate-category-excluder
Ultimate Category Excluder allows you to quickly and easily exclude categories from your front page, archives, feeds, and search results.
Hide Admin Bar
hide-admin-bar
Hide the Admin Bar in WordPress 3.1+.
Hide from Search
mpress-hide-from-search
Hide individual WordPress pages from search engines and/or WordPress searches, such as confirmation and download pages.
Hide Plugins
hide-plugins
Hide installed plugins from clients and other admin users.
Oomph Hidden Tags Developer Profile
2 plugins · 900 total installs
How We Detect Oomph Hidden Tags
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
hidden-tag